Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2024-29834
This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as u…
Pulsar
3.0.4 / 3.2.2+
MEDIUM 6.5
CVE-2024-31134
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was dis…
Teamcity
2024.03+
MEDIUM 6.5
CVE-2024-23451
Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.…
Elasticsearch
8.13.0+
HIGH 7.4
CVE-2023-6400
Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue aff…
Mitigation only
HIGH 8.8
CVE-2024-2915
Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation featu…
Devolutions Server
2024.1.8.0+
HIGH 8.8
CVE-2024-27933
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ipc_pipe()` leads to premature …
Deno
Patch available
MEDIUM 6.5
CVE-2024-27105
Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, gra…
Frappe
14.66.3 / 15.16.0+
HIGH 8.8
CVE-2023-49982
Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perf…
School Fees Management System
No fix yet
MEDIUM 6.5
CVE-2023-50811
An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific …
Visual Access Manager
Mitigation only
CRITICAL 9.8
CVE-2024-28394
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistic…
Mitigation only
CRITICAL 9.1
CVE-2024-2557
A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of…
Food Waste Management System
No fix yet
HIGH 8.0
CVE-2023-50886
Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7.
Legal Pages
1.3.8+
MEDIUM 6.5
CVE-2024-23823
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Comput…
Vantage6
4.2.1+
MEDIUM 6.4
CVE-2023-50726
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily ov…
Argo Cd
2.8.12 / 2.9.7+
MEDIUM 5.3
CVE-2024-1479
The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the wpsp_displ…
Wp Show Posts
1.1.5+
MEDIUM 5.4
CVE-2024-28098
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and off…
Pulsar
2.10.6 / 2.11.4+
MEDIUM 5.5
CVE-2023-45793
A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of …
Siveillance Control
3.1.1+
MEDIUM 6.5
CVE-2024-22133
SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This cou…
Fiori Front End Server
Mitigation only
MEDIUM 5.5
CVE-2024-23250
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watch…
Ipad Os
10.4 / 14.4+
MEDIUM 6.5
CVE-2024-28229
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
Youtrack
2024.1.25893+
HIGH 8.0
CVE-2024-0199
An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 1…
GitLab
16.7.7 / 16.8.4+
HIGH 8.1
CVE-2024-27915
Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of ro…
Sulu
2.4.17 / 2.5.13+
HIGH 7.5
CVE-2024-24761
Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages a…
Galette
Patch available
MEDIUM 5.8
CVE-2024-28174
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
Teamcity
2023.11.4+
HIGH 7.5
CVE-2024-27139
** UNSUPPORTED WHEN ASSIGNED **
Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated…
Archiva
Mitigation only
HIGH 7.5
CVE-2024-27138
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva.
Apache Archiva has a setting to disable user registration, …
Archiva
Mitigation only
HIGH 8.8
CVE-2023-47716
IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual…
Cp4ba Filenet Content Manager
Mitigation only
MEDIUM 5.8
CVE-2024-20291
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalon…
Nx Os
Mitigation only
CRITICAL 9.1
CVE-2024-25170
An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
Mezzanine
No fix yet
MEDIUM 6.5
CVE-2024-24773
Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope.
This issue affects Apa…
Superset
3.0.4 / 3.1.1+